Dough Finance Suffers $1.8 Million Loss in Flash Loan Attack

Crypto hack crypto scam Flash Loan Exploit
Last updated:
Author
Author
Ruholamin Haqshanas
About Author

Ruholamin Haqshanas is a contributing crypto writer for CryptoNews. He is a crypto and finance journalist with over four years of experience. Ruholamin has been featured in several high-profile crypto...

Last updated:
Why Trust Cryptonews
For over a decade, Cryptonews has covered the cryptocurrency industry, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas - from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews
Ad DisclosureWe believe in full transparency with our readers. Some of our content includes affiliate links, and we may earn a commission through these partnerships.

Decentralized finance (DeFi) protocol Dough Finance has lost $1.8 million in digital assets due to a flash loan attack.

Web3 security firm Cyvers detected the attack on July 12, the company said in a post on X.

Cyvers said that the firm reached out to lending protocol Aave to investigate potential impacts on its pools upon detecting multiple suspicious transactions.

“After communicating with the AAVE team, we can confirm that AAVE pools are NOT affected,” it wrote.

Attacker Uses Railgun to Execute Attack

The attacker used the zero-knowledge (ZK) protocol Railgun to execute the attack by swapping the stolen USD Coin for Ether, accumulating a total of 608 ETH valued at around $1.8 million.

Further analysis by Web3 security provider Olympix revealed that the exploit was a result of unvalidated calldata in the “ConnectorDeleverageParaswap” contract.

Olympix explained that the contract failed to properly check the received data during flash loan calls, allowing the attacker to manipulate it to their advantage and carry out the funds’ theft.

While the hack primarily affected users who deposited funds into the exploited contract of Dough Finance, Olympix clarified that the incident did not impact Aave pools.

To mitigate risks, the security provider advised affected users to withdraw their funds to a secure wallet and to refrain from interacting with the protocol until the situation is resolved.

It is worth noting that the Dough Finance attack is not an isolated incident in the crypto space.

According to a security report published by CertiK on July 3, the first half of 2024 witnessed losses of over $1 billion in digital assets due to various security incidents.

Phishing attacks and private key compromises were identified as the main culprits behind these losses, accounting for nearly $500 million and almost $409 million, respectively.

Crypto Market Recovers Over Half of Stolen Funds in Q2

The cryptocurrency market has shown great resilience in the face of adversity, achieving a record recovery rate of 77% for stolen funds in the second quarter of 2024.

In Q2 2024, $347.4 million of the stolen crypto funds were successfully recovered or frozen out of the total $512.9 million lost, according to Hacken’s Web3 Security Report Q2 2024.

“For the second consecutive quarter, the silver lining amid the alarming rate of theft in crypto is the amount of funds recovered,” the report wrote.

It is worth noting that cryptocurrency scams have thrived on X, with analysts attributing a significant portion of all crypto scams to scammers on the platform.

Scam Sniffer, a web3 anti-scam company present on X, conducted an analysis revealing that nearly $50 million is lost each month due to account impersonation on X.com.

Just recently, Binance co-founder Yi He raised concerns about the proliferation of cryptocurrency scams on X, questioning whether Musk would take action to tackle the issue.

More Articles

News
IcomTech Promoter Sentenced To Decade In Federal Prison
Julia Smith
Julia Smith
2024-12-04 22:11:25
DeFi News
Sol Strategies Sets the Stage for Growth with New Validator Acquisition
Hassan Shittu
Hassan Shittu
2024-12-04 19:20:27
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors